exam questions

Exam 300-210 All Questions

View all questions & answers for the 300-210 exam

Exam 300-210 topic 1 question 377 discussion

Actual exam question from Cisco's 300-210
Question #: 377
Topic #: 1
[All 300-210 Questions]

Which description of a correlation policy configuration in the Cisco Firepower Management Center is true?

  • A. You cannot add a host profile qualification to a correlation rule that is triggered by a malware event.
  • B. Deleting a response group deletes the responses of that group.
  • C. Correlation policy priorities override whitelist priorities.
  • D. The system displays correlation policies that are created on all of the domains in a multidomain deployment.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Correlation_Policies.pdf

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
tbanks04
3 years, 6 months ago
The answer is not D. It is A...
upvoted 1 times
...
kplost
3 years, 6 months ago
But A seems better (sorry for spamming) Syntax for Correlation Host Profile Qualifications To constrain a correlation rule based on the host profile of a host involved in the event, add a host profile qualification. You cannot add a host profile qualification to a correlation rule that triggers on a malware event, traffic profile change, or on the detection of a new IP host.
upvoted 1 times
...
kplost
3 years, 6 months ago
Hmm On 6.6 version things have changed so i ve changed my mind . D seems correct Correlation and Multitenancy In a multidomain deployment, you can create correlation policies at any domain level, using whatever rules, white lists, and responses are available at that level. Higher-level domain administrators can perform correlation within or across domains: Constraining a correlation rule by domain matches events reported by that domain's descendants. Higher-level domain administrators can create compliance white lists that evaluate hosts across domains. You can target different subnets in different domains in the same white list.
upvoted 1 times
...
kplost
3 years, 6 months ago
D is wrong Managing Correlation Policies Changes made to active correlation policies take effect immediately. When you activate a correlation policy, the system immediately begins processing events and triggering responses. Note that the system does not generate white list events for non-compliant hosts on its initial, post-activation evaluation. In a multidomain deployment, the system displays correlation policies created in the current domain, which you can edit. It also displays selected correlation policies from ancestor domains, which you cannot edit. To view and edit correlation policies created in a lower domain, switch to that domain. Note The system does not display configurations from ancestor domains if the configurations expose information about unrelated domains, including names, managed devices, and so on.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago